# Supply Chain Attack Uses VS Code Tasks to Deploy Credential Stealer Across npm and Go Ecosystems


A sophisticated supply chain attack has leveraged compromised npm and Go packages to deliver a Python-based information stealer that exploits VS Code's automatic task execution feature. Security researchers at JFrog have identified the campaign as part of a larger North Korean operation targeting software developers and technical personnel, marking a significant evolution in supply chain attack techniques that circumvent modern npm security hardening measures.


## The Threat


The attack centers on two hijacked npm packages uploaded to the registry on May 25, 2026:


  • html-to-gutenberg
  • fetch-page-assets (which lists html-to-gutenberg as a dependency)

  • In parallel, researchers have identified a cluster of compromised Go packages delivering the same payload. Once installed, these packages deploy a multi-stage attack chain culminating in the InvisibleFerret Python backdoor—a credential and cryptocurrency wallet stealer capable of achieving persistent remote access to Windows, Linux, and macOS systems.


    The attack bypasses conventional detection methods by hiding malicious execution within VS Code configuration files, a technique previously attributed to North Korean threat actors. The packages have since been removed from npm, but the attack methodology reveals a troubling gap in modern development tool security.


    ## Background and Context


    This attack represents the third documented sub-campaign of Contagious Interview, a long-running operation that has targeted software developers since 2023. The campaign traditionally relied on fraudulent job interview processes to deliver malware, but this latest iteration exploits the supply chain itself—a far more scalable attack surface.


    Security researcher Paul McCarty and the OpenSourceMalware tracking team have designated this variant as "Fake Font," named after its method of disguising JavaScript malware as TrueType font files (specifically mimicking fa-solid-400.woff2). The Fake Font campaign has been operational since at least January 2026, and this npm/Go package compromise represents a significant escalation in sophistication and reach.


    The attack is particularly notable for its deliberate evasion of npm v12's security hardening measures, which introduced restrictions on lifecycle script execution. Rather than relying on traditional npm hooks (preinstall, postinstall), the attackers embedded execution logic within VS Code workspace configuration—a novel vector that most organizations haven't yet accounted for in their security policies.


    ## Technical Details


    ### Attack Vector: VS Code Auto-Execute Tasks


    The malicious packages include a hidden VS Code task configuration file (.vscode/tasks.json) containing an auto-executing task named "eslint-check." This task is configured with the "runOn: 'folderOpen'" option, which triggers automatic execution under two conditions:


    1. When the package directory is opened as a workspace in VS Code or compatible editors (like Cursor)

    2. When the developer has explicitly allowed automatic tasks for the workspace


    According to JFrog, the task does not recursively execute nested .vscode/tasks.json files—the trigger fires only when the malicious package directory itself is marked as a trusted workspace.


    ### Multi-Stage Infection Chain


    The execution chain unfolds as follows:


    | Stage | Component | Function |

    |-------|-----------|----------|

    | 1 | VS Code Task | Executes hidden command disguised as font file retrieval |

    | 2 | Font File Payload | Contains obfuscated JavaScript (not actual font data) |

    | 3 | Blockchain Dead Drop | Retrieves next-stage payload from TronGrid/Aptos blockchain |

    | 4 | Socket.io Backdoor | Establishes command-and-control connection |

    | 5 | Python Loader | Installs dependencies and downloads infostealer |

    | 6 | InvisibleFerret | Deploys and executes comprehensive credential theft |


    ### Blockchain-Based Dead Drop Resolver


    Rather than relying on traditional C2 infrastructure vulnerable to takedown, the attackers leverage blockchain transaction data as a resilient payload distribution mechanism. The attack chain queries TronGrid and Aptos blockchain networks to retrieve encrypted JavaScript payloads embedded in transaction data.


    This approach offers several operational advantages:


  • Resilience to takedown: Blockchain data cannot be easily removed or centrally disrupted
  • Detection evasion: Legitimate blockchain traffic blends with malicious queries
  • Redundancy: Multiple fallback mechanisms ensure payload delivery even if primary channels fail
  • Geographic distribution: Blockchain nodes operate globally, making geographic blocking ineffective

  • The Socket.io backdoor established in the fourth stage handles secondary command-and-control, enabling the attackers to:


  • Execute arbitrary shell commands
  • Harvest clipboard contents
  • Perform file system operations and uploads
  • Manage running processes
  • Execute additional JavaScript payloads
  • Deploy the Python infostealer component

  • ### Credential and Artifact Theft Capabilities


    The InvisibleFerret Python component provides comprehensive data exfiltration:


    Browser & Password Managers:

  • Chromium-based browsers (Chrome, Edge, Brave, Opera)
  • Mozilla Firefox
  • Saved passwords and autofill data
  • Browser extensions and stored authentication tokens

  • Cryptocurrency & Wallets:

  • Private wallet keys
  • Seed phrases
  • Exchange authentication credentials
  • Hardware wallet configuration data

  • Developer-Specific Artifacts:

  • Git credentials and SSH keys
  • GitHub CLI configuration (hosts.yml)
  • GitHub Desktop logs
  • VS Code settings and extensions
  • Global npm/yarn configuration
  • API keys and tokens stored in developer environments

  • System Credential Storage:

  • Windows Credential Manager
  • Linux Secret Service
  • KDE Wallet
  • macOS Keychain
  • Cloud storage credentials (AWS, GCP, Azure)

  • ## Implications for Organizations


    ### Supply Chain Risk Amplification


    The use of npm and Go packages as attack vectors represents a fundamental threat to software supply chains. Unlike traditional malware distribution, package managers offer:


  • Implicit trust: Developers install packages without expecting malicious content
  • Ecosystem scale: Compromised packages can reach thousands of projects simultaneously
  • Minimal friction: Installation requires only adding a dependency line

  • This attack demonstrates that package manager compromise can bypass infrastructure security entirely. Even air-gapped networks and hardened CI/CD systems cannot prevent the risk if malware is introduced through a trusted development dependency.


    ### Developer Targeting as Strategic Priority


    The campaign's focus on stealing developer credentials, cryptocurrency wallets, and SSH keys reveals a sophisticated threat model. Compromised developer credentials enable attackers to:


  • Access private repositories and proprietary code
  • Modify open-source libraries (extending the attack downstream)
  • Deploy to cloud infrastructure using developer credentials
  • Steal cryptocurrency holdings (particularly relevant for blockchain-focused developers)
  • Establish persistence across organizational boundaries

  • ### Evasion of Standard Security Controls


    This attack specifically circumvents technologies that organizations have invested in:


  • npm security hardening (v12): Attacks avoid lifecycle scripts entirely
  • Supply chain scanning: Many tools don't inspect .vscode/ directories for malicious content
  • Container-based isolation: The attack executes within developer workstations, outside containerized environments
  • Endpoint detection and response (EDR): Initial execution within VS Code may evade process-based detection

  • ## Recommendations


    ### For Development Teams


    1. Review VS Code Configuration: Audit all .vscode/tasks.json files in your repositories and projects for unfamiliar tasks, particularly those configured to run automatically on folder open.


    2. Restrict Automatic Task Execution: Disable the "Allow automatic tasks for this workspace" setting in VS Code unless explicitly required for your development workflow.


    3. Audit Package Dependencies: Scan all npm and Go dependencies for recent updates or additions. Cross-reference upload dates with suspicious activity.


    4. Credential Rotation: If you installed either html-to-gutenberg or fetch-page-assets, rotate all credentials, SSH keys, API tokens, and browser passwords as a precaution.


    5. Cryptocurrency Wallet Review: Developers using cryptocurrency should review wallet activity and consider moving funds from potentially compromised wallets to new addresses.


    ### For Organizations


    1. Supply Chain Inventory: Maintain a complete inventory of all third-party dependencies across all development projects and environments.


    2. Automated Dependency Scanning: Implement tools that scan for known compromised packages and alert teams immediately upon detection.


    3. Workspace Trust Policy: Establish policies requiring developers to explicitly review and approve workspace trust settings before opening unfamiliar projects.


    4. Incident Response Planning: Develop procedures for responding to supply chain compromises, including credential rotation, forensic analysis, and downstream notification.


    5. Developer Training: Educate developers about supply chain risks, VS Code security features, and the importance of reviewing code execution settings.


    ## HackWire Analysis


    This attack represents a inflection point in supply chain security threats. While npm and PyPI compromises aren't new, the combination of three factors makes this campaign particularly significant.


    First, the deliberate evasion of npm v12's security hardening suggests the threat actors are actively studying defenses and adapting accordingly. They didn't just find a vulnerability—they engineered around specific security controls that organizations believed would prevent exactly this kind of attack. This cat-and-mouse dynamic will accelerate; if npm v13 closes this loophole, attackers will find the next one.


    Second, the connection to North Korea's Contagious Interview campaign and the Fake Font designation signal that nation-state actors are treating developer targeting as a strategic priority. Developers have access to infrastructure, credentials, and secrets that offer asymmetric value to attackers. A single compromised developer credential can grant access to millions of users' data. The investment in sophisticated multi-stage payloads, blockchain-based resilience, and persistent backdoors demonstrates commitment that goes beyond financially-motivated cybercriminals.


    Third, this attack exploits the implicit trust model at the heart of open-source ecosystems. npm packages install without prompting users to review configuration files or execution settings. VS Code workspace configuration gets less scrutiny than code itself. Organizations audit their own code meticulously but treat dependencies as black boxes. That trust model is increasingly untenable.


    The broader lesson: supply chain attacks won't be stopped by detecting malicious code—they'll be stopped by assuming all code is potentially malicious until proven otherwise. That means cryptographic verification of package integrity, scanning for execution hooks in unexpected places (configuration files, not just scripts), and building security architecture that assumes developer machines will eventually be compromised.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Supply Chain Security](https://www.hackwire.news/category/supply-chain) coverage
  • Cross-reference with [Malware](https://www.hackwire.news/category/malware) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)